PEN-200 Buffer Overflow Fundamentals Practice Question
You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?
⚠ Common exam trap
Candidates often confuse the EIP/RIP register with the stack pointer (ESP/RSP). They forget that the return address on the stack is what determines the next instruction pointer value.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The saved Return Address on the stack
To redirect the execution flow, you must overwrite the saved Return Address on the stack. When a function finishes, the CPU pops the value at the saved EIP/RIP location into the Instruction Pointer. By overflowing the buffer and reaching this specific memory location, you gain control over the program's subsequent execution path, which is the foundational concept for stack-based buffer overflow exploitation in the PEN-200 curriculum.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ESP register
Why it's wrong here
The Extended Stack Pointer (ESP) tracks the current top of the stack. While you might use it to locate your shellcode, overwriting it does not directly redirect the execution flow when the current function concludes. It is a secondary mechanism used for stack alignment and tracking rather than flow hijacking.
- ✗
The EAX register
Why it's wrong here
The EAX register is primarily used as an accumulator for arithmetic operations and return values from function calls. Overwriting this register will not cause the CPU to jump to a new memory address upon function completion. It is not involved in the stack frame's structural return mechanism.
- ✓
The saved Return Address on the stack
Why this is correct
The saved Return Address sits just above the local variables on the stack. When the function epilogue executes, the CPU performs a RET instruction, which pops this specific stack value directly into the EIP register. Controlling this value is the direct way to hijack the program control flow.
- ✗
The EBP register
Why it's wrong here
The EBP or Base Pointer is used to reference local variables and function arguments. While overwriting the saved base pointer can disrupt the stack frame, it does not immediately redirect the instruction pointer to your shellcode. It usually leads to a crash when the program attempts to restore the stack.
Visual reference
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.